From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:47324) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fsqv8-0000ag-QE for guix-patches@gnu.org; Thu, 23 Aug 2018 10:49:13 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fsqv2-0005Zs-V1 for guix-patches@gnu.org; Thu, 23 Aug 2018 10:49:08 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:53961) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fsqv2-0005ZY-8x for guix-patches@gnu.org; Thu, 23 Aug 2018 10:49:04 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1fsqv0-0006HK-Dw for guix-patches@gnu.org; Thu, 23 Aug 2018 10:49:04 -0400 Subject: [bug#32451] [PATCH] gnu: openssh: Don't allow remote username enumeration Resent-Message-ID: From: ludo@gnu.org (Ludovic =?UTF-8?Q?Court=C3=A8s?=) References: <20180821151726.GA2463@jasmine.lan> Date: Thu, 23 Aug 2018 16:48:28 +0200 In-Reply-To: <20180821151726.GA2463@jasmine.lan> (Leo Famulari's message of "Tue, 21 Aug 2018 11:17:26 -0400") Message-ID: <87bm9tnnpf.fsf@gnu.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: 32451@debbugs.gnu.org Leo Famulari skribis: > The bug was assigned CVE-2018-15473. > > This patch is basically identical to the one being used by Debian. I > tested with the POC from oss-sec [0], which required some changes to the > Paramiko package. > > Pushed as 6cd2c4a83cc2baa387d04979b489bee2429cc39d Thank you! Ludo=E2=80=99.